fix(yq): reject lossy numbers and harden coverage - #2269
Merged
Merged
Conversation
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
bashkit | 7feabe7 | Commit Preview URL Branch Preview URL |
Aug 06 2026, 03:22 AM |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Hardened the jq-backed
yqbuiltin with substantially broader compatibility and security coverage. Portable specs now cover assignments, file/stdin ordering, JSON streams, formatting, combined/attached flags, exit status, null input, Unicode, and automatic JSON input detection. Integration and property tests cover multi-file aggregate limits, YAML aliases and duplicate keys, parser depth/document bounds, shared jq work budgets, bounded deterministic diagnostics, and arbitrary YAML/filter inputs.Replaced the stale legacy
yamlfuzzer—which only exercised a removed command surface—with a feature-enabledyqfuzzer that probes the real builtin and varies formats, filters, stdin/in-place paths, and execution limits. Added atomic in-place failpoints for allocation, mode preservation, rename, and VFS write failures. A locked 10-case mikefarah/yq v4.53.3 corpus provides portable parity coverage and can run against a live oracle when available.Non-finite YAML numbers now fail deterministically instead of being silently converted to JSON
null.Why
The initial
yqimplementation had useful behavior tests, but its fuzz target did not invokeyq, atomic replacement failure stages were not injectable, and important parser/resource/compatibility boundaries were not locked down. Edge-case auditing also found silent data loss for.nanand infinities.Before / After
Before:
After:
End-to-end smoke proof:
Validation:
just pre-pr; 17 failpoint tests; locked fuzz-target build; 100-run fuzz smoke; locked and live mikefarah/yq v4.53.3 differential corpus.Risk
Checklist